HIGH 8.1 NVD
CVE-2026-24791
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
References
- https://blog.gitea.com/release-of-1.26.2/
- https://github.com/go-gitea/gitea/pull/37118
- https://github.com/go-gitea/gitea/releases/tag/v1.26.2
- https://github.com/go-gitea/gitea/security/advisories/GHSA-wrr5-99h5-gq57
- https://github.com/go-gitea/gitea/security/advisories/GHSA-wrr5-99h5-gq57
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-08-13 via NVD.
vulnfeed aggregates 10812 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.